VYPR

Agent Zero

by Agent0ai

Source repositories

CVEs (2)

  • CVE-2026-47118MedMay 27, 2026
    risk 0.35cvss 6.5epss

    Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by supplying crafted paths to the image file serving endpoint, which relies solely on an extension allowlist while the path containment check is…

  • CVE-2026-47119MedMay 27, 2026
    risk 0.33cvss 6.1epss

    Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript in the application origin by serving SVG files through the image_get API endpoint without Content-Security-Policy, X-Content-Type-Options, or…